Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
Description
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, AgentRuntime promises scoped file access under a configured sandbox basePath, but its path containment checks use raw string prefix tests. A sandbox base such as /tmp/network-ai-sandbox also matches a sibling path such as /tmp/network-ai-sandbox_evil/secret.txt. An agent/user that can call AgentRuntime.readFile() or AgentRuntime.listDir() can read or list files outside the intended sandbox when the target path is in a sibling directory sharing the base path prefix. This breaks the documented sandbox boundary. The issue is fixed in v5.12.2. SandboxPolicy.resolvePath() and isPathAllowed() now use separator-anchored prefix checks (resolved === base || resolved.startsWith(base + path.sep)) for both the allow-list and block-list. A sibling directory that merely shares a name prefix (e.g. /srv/app-evil vs base /srv/app) is no longer treated as in-scope.
Affected products
2- Range: <5.12.2
- Range: <5.12.2
Patches
Vulnerability mechanics
References
3- github.com/Jovancoding/Network-AI/commit/a59c13a1f0ce0e8a0779a90343eef92fac5ab4c3mitrex_refsource_MISC
- github.com/Jovancoding/Network-AI/releases/tag/v5.12.2mitrex_refsource_MISC
- github.com/Jovancoding/Network-AI/security/advisories/GHSA-jvcm-f35g-w78pmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.